cbcvebase.
CVE-2015-7973
published 2017-01-30

CVE-2015-7973: NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the…

PriorityP333medium6.5CVSS 3.1
AVNACHPRNUINSUCNILAH
EPSS
3.36%
87.4th percentile
NTP before 4.2.8p6 and 4.3.x before 4.3.90, when configured in broadcast mode, allows man-in-the-middle attackers to conduct replay attacks by sniffing the network.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debianntp< ntp 1:4.2.8p7+dfsg-1 (bullseye)ntp 1:4.2.8p7+dfsg-1 (bullseye)
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd
freebsdfreebsd>= 10.0 < 10.110.1
ntpntp< 4.2.84.2.8
ntpntp
ntpntp>= 0 < 1:4.2.8p7+dfsg-11:4.2.8p7+dfsg-1
ntpntp>= 0 < 1:4.2.6.p5+dfsg-3ubuntu2.14.04.101:4.2.6.p5+dfsg-3ubuntu2.14.04.10
ntpntp>= 0 < 1:4.2.8p4+dfsg-3ubuntu5.31:4.2.8p4+dfsg-3ubuntu5.3
ntpntp>= 4.3.0 < 4.3.904.3.90
paloaltopan-os

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv6.5MEDIUM
vendor_cisco6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.